diff --git a/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml b/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml index 07b8ab10c..e51b3c716 100644 --- a/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml +++ b/rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml @@ -17,6 +17,7 @@ tags: logsource: category: ps_script product: windows + definition: Script block logging must be enabled detection: selection_args_exc: ScriptBlockText|contains: